Re: [c-nsp] CPU anomoly on 3560G when adding a BGP peer

2007-09-13 Thread Wyatt Mattias Ishmael Jovial Gyllenvarg
Ivan, Worked like a sharm. I did not know the shared memory switches had these format options on the CEF memory. I was told it was dynamic, but I guess thats a partial truth. Thanks alot! Best regards Mattias Gyllenvarg Omnitron Sweden From: Ivan Gasparik [EMAIL PROTECTED] To:

[c-nsp] Cisco 877/1811/WIC-ADSL- M - Annex M supply question

2007-09-13 Thread Skeeve Stevens
Hey guys, Does anyone know if Annex-M is used in the US? My supplier here has talked to all his suppliers in the US and the feedback he has received is that the Annex-M versions of the 877/1811 and ADSL WIC, will not be released in the US and is only an APAC product. This doesn't

Re: [c-nsp] Cisco 877/1811/WIC-ADSL- M - Annex M supply question

2007-09-13 Thread Frank Bulk
Both Occam and Calix have or have in the pipeline Annex-M DSL line cards. So, yes, Annex-M is in the U.S. Frank -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Skeeve Stevens Sent: Thursday, September 13, 2007 2:45 AM To: cisco-nsp@puck.nether.net

[c-nsp] Troubleshooting OSPF

2007-09-13 Thread Vincent De Keyzer
Hello people, I have a (Cisco + Foundry) OSPF network that is causing me some trouble. Sometimes routes do disappear from the routing table while they should not. Does anybody have a good document about troubleshooting that sort of problems? I guess it involves looking at the OSPF

Re: [c-nsp] cap'ing each host/ip to bw limits

2007-09-13 Thread Alex
Matthew, microflow policing on 65XX comes to mind... Rgds Alex - Original Message - From: matthew zeier [EMAIL PROTECTED] To: cisco-nsp@puck.nether.net Sent: Thursday, September 13, 2007 5:35 AM Subject: [c-nsp] cap'ing each host/ip to bw limits Is there some QOS magic to limit each

Re: [c-nsp] cap'ing each host/ip to bw limits

2007-09-13 Thread Phil Bedard
What platform are you using? The 6500/7600 w/SUP720 can do per-user microflow policing, which would probably accomplish what you are after. As for the router type platforms like the 7200/GSR I'm not aware of any such feature outside of dial profiles. Phil On Sep 13, 2007, at 12:35 AM,

[c-nsp] SNMP OID for IP route

2007-09-13 Thread Vincent De Keyzer
Hello, is there a way to specify the mask information when querying a router's IP routing table via SNMP ? My problem is that snmpwalk -c community -v 2c router ipRouteIfIndex.10.0.0.0 only returns the most specific match, in case the router for instance knows both 10.0.0.0/24 and

Re: [c-nsp] SNMP OID for IP route

2007-09-13 Thread Phil Mayers
On Thu, 2007-09-13 at 14:33 +0200, Vincent De Keyzer wrote: Hello, is there a way to specify the mask information when querying a router's IP routing table via SNMP ? My problem is that snmpwalk -c community -v 2c router ipRouteIfIndex.10.0.0.0 only returns the

Re: [c-nsp] 3550 as a BGP Router

2007-09-13 Thread Tom Storey
Plug the 2610 into the 3550? Or use a 16 port switch NM and plug your peers into that. Obviously limited to 16 peers with the NM, but either way thats how you'd do it. - Original Message - From: Jon Lewis [EMAIL PROTECTED] To: Adrian Chadd [EMAIL PROTECTED] Cc: cisco-nsp@puck.nether.net

Re: [c-nsp] hardware load balancer?

2007-09-13 Thread Adam Greene
Hi all, I received a couple requests to summarize the responses I received to this inquiry. I received many responses, on and off-list (and also from another mailing list). F5 was mentioned most frequently in a positive way IOS SLB on 7200/6500 and Foundry were also mentioned positively and

Re: [c-nsp] cap'ing each host/ip to bw limits

2007-09-13 Thread matthew zeier
Phil Bedard wrote: What platform are you using? The 6500/7600 w/SUP720 can do per-user microflow policing, which would probably accomplish what you are after. As for the router type platforms like the 7200/GSR I'm not aware of any such feature outside of dial profiles. 3845 so I'm

Re: [c-nsp] vty access-list

2007-09-13 Thread Tom Storey
Hi, I am trying to filter SSH access on a router from outside by source and destination ip address. To be more clear, the source SSH access is the outside /24 network x.x.x.x, and the destination SSH IP is one of the router's ip's. I want to be able to cut the ssh listening on all the ip's from

Re: [c-nsp] 3550 as a BGP Router

2007-09-13 Thread Arie Vayner (avayner)
One thing to worry about in 3550 is the number of actual routes installed in the FIB, as it installs them in the HW forwarding TCAM, which does not have too much room (something like 2000 should be the safe limit). If all you need is 100 routes, then it should be fine. Arie -Original

Re: [c-nsp] vty access-list

2007-09-13 Thread Aaron Daubman
Catalin, ... Is this a normal behavior of the IOS, to block access to all the ip's, including to the one that is supposed to be allowed? While not explicitly called out, I believe the intent is to use a 'standard' access list with one's vty access-class statements. To that end, an extend

Re: [c-nsp] vty access-list

2007-09-13 Thread Robert E. Seastrom
Try using an access-class on the VTY and a simple acl (number 1-99) instead. ---rob C and C Dominte [EMAIL PROTECTED] writes: Hi, I am trying to filter SSH access on a router from outside by source and destination ip address. To be more clear, the

Re: [c-nsp] vty access-list

2007-09-13 Thread Fred Reimer
If the device supports CPP can't you put an ACL on the control-plane to handle all interfaces at once? Fred Reimer, CISSP Senior Network Engineer Coleman Technologies, Inc. 954-298-1697 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Aaron Daubman Sent:

Re: [c-nsp] vty access-list

2007-09-13 Thread Collins, Richard (SNL US)
Yes I think that you have to use a standard access-list on the VTY. I believe to only allow ssh you could just allow ssh as a transport. router(config)#line vty 0 4 router(config-line)#transport input ? acercon Remote console for ACE-based blade all All protocols lat DEC LAT

Re: [c-nsp] cap'ing each host/ip to bw limits

2007-09-13 Thread matthew zeier
So I wonder if there's an alternative method to prevent over saturation (or at least reduce it's impact on everyone else)... Phil Bedard wrote: Yes, unless they are static IP addresses and you configure policing for every single individual IP, but that doesn't sound like much fun... Phil

Re: [c-nsp] cap'ing each host/ip to bw limits

2007-09-13 Thread Phil Bedard
Yes, unless they are static IP addresses and you configure policing for every single individual IP, but that doesn't sound like much fun... Phil On Sep 13, 2007, at 9:29 AM, matthew zeier wrote: Phil Bedard wrote: What platform are you using? The 6500/7600 w/SUP720 can do per- user

Re: [c-nsp] cap'ing each host/ip to bw limits

2007-09-13 Thread Phil Bedard
Well you can limit the bandwidth based on application, such that peer to peer or ftp downloads are not maxing out all of your available bandwidth.There are some good NAC (network access control) inline devices from places like Elacoya or Packeteer which can limit on per- user and

Re: [c-nsp] hardware load balancer?

2007-09-13 Thread Dean Smith
There's probably a good reason no-one recommended the ACE Give it another year and the code might be fit for public use. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Arie Vayner (avayner) Sent: 13 September 2007 15:18 To: Adrian Chadd; Adam Greene Cc:

Re: [c-nsp] vty access-list

2007-09-13 Thread Jared Mauch
On Thu, Sep 13, 2007 at 08:55:07AM -0700, Collins, Richard (SNL US) wrote: Yes I think that you have to use a standard access-list on the VTY. I No, you can use an extended access-list as well. 2610(config-line)#access-class ? 1-199 IP access list 1300-2699 IP expanded access

[c-nsp] Cisco 3550 traffic policing/QoS limitations?

2007-09-13 Thread TCIS List Acct
According to: http://www.cisco.com/warp/public/473/153-2.gif It appears that there are limitations on the number of policers that you can use. What isn't clear is how these apply -- in a nutshell, what we want to be able to do is define a policer that limits ingress/egress traffic to 10M (we

[c-nsp] 7600: etherchannel and aggregators

2007-09-13 Thread Dmitry Kiselev
Hello! I catch etherchannel aggregators problem on by 7600 box. :( Two ports (g1/11, g1/12) just configured couldn't be aggregated to LACP driven channel. Here is config and debug output: interface GigabitEthernet1/11 switchport switchport trunk encapsulation dot1q switchport mode trunk

Re: [c-nsp] 7600: etherchannel and aggregators

2007-09-13 Thread Michael K. Smith - Adhost
Hello Dmitry: snip Sep 13 18:38:00.091: idbman_get_agport: 14/4 Po2A(O) Sep 13 18:37:59.762: %EC-SP-5-CANNOT_BUNDLE_LACP: Gi1/11 is not compatible with aggregators in channel 2 and cannot attach to them (trunk mode of Gi1/11 is trunk, Gi1/16 is dynamic) Are you sure Gi1/16 is really the

[c-nsp] vty access-list

2007-09-13 Thread Leonardo Gama Souza
If your router can do it, try to use ip receive access-list. Good luck. Cheers, Leonardo Gama ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at

Re: [c-nsp] spanning-tree optimize bpdu transmission

2007-09-13 Thread Dale W. Carder
Looking through my notes, in 2004 I saw this show up in a config somewhere (can't recall if it was a 6500 or a dsbu switch), and it was ack'd as CSCeb13403, a cosmetic bug. Cheers, Dale On Sep 10, 2007, at 12:38 PM, Richard Stern wrote: The command spanning-tree optimize bpdu transmission is

Re: [c-nsp] vty access-list

2007-09-13 Thread Dale W. Carder
Yes. This is what we do for SNMP. Dale On Sep 13, 2007, at 10:12 AM, Fred Reimer wrote: If the device supports CPP can't you put an ACL on the control-plane to handle all interfaces at once? ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

Re: [c-nsp] Troubling IPSec issues with a 6500

2007-09-13 Thread Lars Fenneberg
Hi! Quoting Pete S. ([EMAIL PROTECTED]): One issue we have had with ipsec is the adjust-mss command is not available on the 6500 until a later release. I have not checked up if it is in the latest SXF yet however. Until it is, You will need to clear the DF bit on all traffic exiting the

Re: [c-nsp] Cisco 3550 traffic policing/QoS limitations?

2007-09-13 Thread Tom Zingale \(tomz\)
The 3550 QoS policer usage is detailed in the configuration guide: http://www.cisco.com/en/US/docs/switches/lan/catalyst3550/software/relea se/12.2_25_see/configuration/guide/swqos.html#wp1044737 The same policy-map with policer can be attached to each port and in your case you can use up to 1

[c-nsp] Access-Points - Dhcp Relay

2007-09-13 Thread Velasquez Venegas Jaime Omar
Hi. We have just deployed our wireless network with some Cisco access points.We would like access point act as dhcp relay for each configured ssid-vlan.I've already checked guides but it seems there's no reference to this dhcp relay scenario in Access points. What interfaces should i configure ip

Re: [c-nsp] Access-Points - Dhcp Relay

2007-09-13 Thread Asbjorn Hojmark - Lists
We have just deployed our wireless network with some Cisco access points. We would like access point act as dhcp relay for each configured ssid-vlan. The access point (if 'fat') is just a bridge, so there's no DHCP relay functionality available (or necessary). Use whatever router you have in

Re: [c-nsp] cap'ing each host/ip to bw limits

2007-09-13 Thread Masood Ahmad Shah
Packeteer packet shaper is bestGo for it... Regards, Masood Ahmad Shah -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Phil Bedard Sent: Thursday, September 13, 2007 9:08 PM To: matthew zeier Cc: cisco-nsp@puck.nether.net Subject: Re: [c-nsp]

Re: [c-nsp] Access-Points - Dhcp Relay

2007-09-13 Thread Velasquez Venegas Jaime Omar
Thanks.However, the ip helper-address is available in every interface (dot11radio,fastethernet and BVI) Any explanation? Thank you -Original Message- From: Asbjorn Hojmark - Lists [mailto:[EMAIL PROTECTED] Sent: Jueves, 13 de Septiembre de 2007 03:47 p.m. To: Velasquez Venegas Jaime

Re: [c-nsp] hardware load balancer?

2007-09-13 Thread jim bartus
Its also crushing an ant with a nuke if you only need 5 - 20mbps. -jim On 9/13/07, Dean Smith [EMAIL PROTECTED] wrote: There's probably a good reason no-one recommended the ACE Give it another year and the code might be fit for public use. -Original Message- From: [EMAIL

[c-nsp] AP's WDS and Fast Secure Roaming

2007-09-13 Thread Steve Wright
Hi all, Before I get really into the nitty gritty of (attempt) at doing my first AP config supporting roaming between AP's; does anyone have any pointers or base configs that I could to get me started? The thing I'm not getting at the moment, which could be my stupidity is how to do the

[c-nsp] Looking for suggestions on how to link old colo with the new colo for routing purposes until new circuits are in place

2007-09-13 Thread Dan Troxel
We are in the process of merging three colo facilities into one new facility. However, we are getting into heavy delays from two of our telco providers. We are looking for a solution for IP traffic (subnet) routing while we are in the process of the move, and during our waiting period from our

Re: [c-nsp] cap'ing each host/ip to bw limits

2007-09-13 Thread Phil Mayers
On Thu, 2007-09-13 at 08:54 -0700, matthew zeier wrote: So I wonder if there's an alternative method to prevent over saturation (or at least reduce it's impact on everyone else)... It's a layer8 solution, but we've had good luck with bandwidth quotas. Use netflow to account per-IP, and kick

[c-nsp] CISCO Networkers Invite (Pipe Drinks) (Brisbane.au)

2007-09-13 Thread Skeeve Stevens
Posting on behalf of Pipe Networks …Skeeve Join us for a night of industry networking PIPE Networks is hosting their annual Brisbane networking event, coinciding with Cisco Networkers 2007. The night will be an excellent opportunity for industry professionals in the telecommunications

Re: [c-nsp] cap'ing each host/ip to bw limits

2007-09-13 Thread a. rahman isnaini r. sutan
Less budget : Mikrotik 2.9 Better bit : ETINC Good luck. a. rahman isnaini r. sutan - Original Message - From: Masood Ahmad Shah [EMAIL PROTECTED] To: 'Phil Bedard' [EMAIL PROTECTED]; 'matthew zeier' [EMAIL PROTECTED] Cc: cisco-nsp@puck.nether.net Sent: Friday, September 14, 2007 3:39

Re: [c-nsp] Access-Points - Dhcp Relay

2007-09-13 Thread a. rahman isnaini r. sutan
- Original Message - From: Velasquez Venegas Jaime Omar [EMAIL PROTECTED] To: Asbjorn Hojmark - Lists [EMAIL PROTECTED] Cc: cisco-nsp@puck.nether.net Sent: Friday, September 14, 2007 4:23 AM Subject: Re: [c-nsp] Access-Points - Dhcp Relay : : Thanks.However, the ip helper-address is

[c-nsp] BGP -- ADSL as failover link

2007-09-13 Thread Steve Bertrand
Hi all, Out of curiosity... I have a 100Mb fibre Ethernet connection, and an ADSL connection to a single provider via one router at my end. Currently, said provider maintains an EIGRP setup between our router and their own, so when the LANx connection goes down, our /21 is transits over the